# Security policy panda-rpki processes untrusted network data and is not yet a supported production release. A public security-reporting channel, response targets, and supported release branches have not been assigned. Do not disclose suspected vulnerabilities in a public issue, pull request, or commit until a public reporting address is published. Release artifacts and container images must never include credentials, production state, private registry configuration, or internal host names. The first supported release will publish a security contact, disclosure process, update policy, and supported-version table in the documentation site.